Z2.06.3Personal and shared contextdesign

Personal and shared context have different capture boundaries

Aliases: shared context · personal context · capture boundary

What it is

Type context by what it describes: personal context describes one person — someone's location, activity, state. Shared context describes a space or a group — the mood of the living room, the crowd present, the joint activity underway. Their capture boundaries differ: personal context can in principle be consented to by that person, on that person's device; shared context physically involves several people, and no single person's consent covers the rest.

Where the boundary sits is a design decision, not a fact of nature: "someone is in this room" can be sensed by a room sensor (shared context) or aggregated from the phones of everyone present (an aggregate of personal context) — one fact, two capture routes, entirely different privacy properties.

Why it happens

The signals of shared context are physically inseparable. The room microphone receives a mixed soundfield; the radar sees "three people"; the camera frames the whole sofa — there is no way to capture "only my share". Once a room-level device is on, its capture scope is the space and everyone in it.

This creates a consent-structure mismatch: the person who signed the terms of service is the account owner, while those covered by the room sensor are the spouse, the children, the visiting friend — consenters and the captured are different sets. Personal context carries no such mismatch: whose data, whose consent.

The boundary also fixes the possibility of exit. Personal context can be abandoned unilaterally (turn off your own location sharing); a non-owner inside shared context can only exit by physically leaving the space or persuading the owner to remove the device — the right of withdrawal does not sit with the person being captured. These two properties — inseparability and no unilateral exit — are why the capture boundary for shared context must be drawn one notch tighter than for personal.

Where it stops holding

  • Personal and shared convert into each other. Partners sharing location voluntarily turn personal context shared; when the relationship ends the sharing must be revocable, or "temporary sharing" becomes a permanent record.
  • Power asymmetry inside a household degrades "personal consent". Children hold no veto over a camera; an economically dependent partner's "yes" is not always free. Treating signature-on-agreement as the whole legitimacy of capture systematically overstates consent quality in shared spaces.
  • Aggregation does not automatically de-sensitise. Three people's locations put together can reveal a fourth's whereabouts (the roommate who is never in the presence log). A system can be scrupulously personal-only in capture and still leak others through the assembled shared picture.

Applying it

  • Capture priority: whatever can be inferred from personal devices, do not sense with room devices. For "is anyone home", try aggregating presence phones first and keep room sensors as fallback (genuinely needed for burglary scenarios, and then visibly indicated).
  • Default to scope minimisation for room-level sensing: presence detection needs an occupancy sensor, not a camera; "quiet or loud" needs a sound-level meter, not audio content.
  • Make the capture state of shared context visible to everyone present — guests without accounts included; write the exit path for the captured, not only for the account owner.
  • How to check: list the data sources behind every automation and inspect each for "a source consented to by one person that covers several". Every such source either gains notification and visibility, or is demoted to personal-device capture.

Related

  • Same group: Z2.06.1 Context splits into physical and social dimensions · Z2.06.2 Static context like location changes slowly; dynamic context like activity changes fast · Z2.06.4 Dimensions can contradict: location right, activity wrong
  • Nearby: Z6.03 Privacy in shared spaces · Z6.04 Presence of non-users
  • Search terms: personal context · shared context · multi-user sensing · bounded consent

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z2.06.3